Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cve-'

View all threats tagged with 'cve-'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-

Threats Tagged 'cve-'

Click on any threat for detailed analysis and mitigation recommendations

CopyEscape: Container-to-host arbitrary file write via docker cp (CVE-2026-17106)CVE-2026-17106
0

CVE-2026-17106, known as CopyEscape, is a high-severity vulnerability in Docker's 'docker cp' command that allows a malicious container to write arbitrary files to the host filesystem. The flaw stems from a filesystem race condition during archive creation combined with unsafe symbolic link handling during extraction. This can lead to arbitrary file creation or overwriting on the host and potentially code execution depending on the privileges of the Docker CLI user. Docker has released official fixes in Docker Engine/CLI version 29.7.2 and later, Docker Desktop 4.86.0 and later, and Docker Sandboxes 0.38.0 and later.

Join the discussion
New WordPress Pre-Auth XSS (CVE-2026-64638) Could Lead to RCE: Have you patched your instances yet?CVE-2026-64638
0

CVE-2026-64638 is a high-severity pre-authentication reflected cross-site scripting (XSS) vulnerability in WordPress login pages that can lead to remote code execution (RCE) under specific conditions. The flaw allows attacker-controlled JavaScript to execute in the browser of a visitor after a failed login attempt. Exploitation requires a logged-in administrator to interact with an attacker-controlled page, potentially enabling PHP code execution on the server. The vulnerability affects default WordPress installations and was patched in WordPress 7.0.3 and backported to versions back through 4.7. Versions older than 4.7 remain vulnerable. WordPress recommends immediate updating, and automatic background updates should apply the patch automatically. No in-the-wild exploitation has been reported as of the advisory date.

Join the discussion
Researchers altered a forensic DNA evidence file in 45 minutes and the analysis software raised no warning (CVE-2026-17583)CVE-2026-17583
0

CVE-2026-17583 is a vulnerability in Thermo Fisher's Applied Biosystems human identification instruments where forensic DNA evidence files (.fsa and .hid) can be altered between creation and analysis without detection. Researchers demonstrated that these files could be modified in about 45 minutes to merge DNA profiles into a single file that appears unaltered since 2015. Thermo Fisher issued an update adding digital signatures to files created after the patch, but no retroactive validation exists for older files, and some end-of-life products do not receive updates. This leaves historical forensic DNA evidence files vulnerable to undetectable tampering.

Join the discussion
CVE-2026-6837: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') in Zyxel WAX650S firmwareCVE-2026-6837
0

CVE-2026-6837 is a post-authentication OS command injection vulnerability in the export-cgi CGI program of Zyxel WAX650S firmware up to version 7.10(ABRM.4)C0. An attacker with administrator privileges could exploit this flaw to execute arbitrary OS commands on the device. The vulnerability has a high severity rating with a CVSS score of 7.2. No official patch or remediation guidance is currently provided by the vendor.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cve-
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses